PT-2025-44451 · Ibm · Ibm Tivoli Monitoring

Aleksandr Tlyapov

·

Published

2025-10-30

·

Updated

2025-11-07

·

CVE-2025-3356

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Tivoli Monitoring versions 6.3.0.7 through 6.3.0.7 Service Pack 21
Description The software contains a directory traversal flaw. A remote attacker can exploit this by sending specially crafted URL requests containing "dot dot" sequences (../) to view, overwrite, or append to arbitrary files on the system. The vulnerability allows manipulation of URL requests to traverse directories, potentially enabling unauthorized access to files within the server’s filesystem.
Recommendations Versions prior to 6.3.0.7 Service Pack 22 should be updated.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-3356

Affected Products

Ibm Tivoli Monitoring